Privacy Policy
Effective date: October 4, 2026
RoamFolio is an iOS app developed by Nossa ("Nossa," "we," "us," or "our") that helps you collect passport-style stamps for real-world cities you visit, connect with friends, and send postcards. This Privacy Policy explains what information the app accesses, how it's used, and the choices you have. RoamFolio has no user accounts of its own outside of Sign in with Apple, and most of what it does happens almost entirely on your device or inside your own iCloud account, using Apple's own frameworks (CoreLocation, Photos, CloudKit, Vision, and Apple Intelligence's on-device language model). For your RoamPost profile and friends, your avatar, and the in-app coin balance used for optional postcard-delivery upgrades, RoamFolio talks to small services Nossa operates and hosts itself, described below.
1. Information We Collect
Location data
RoamFolio asks for location access ("while using the app") to show which stamping stations are nearby and to verify you're within range of one before letting you collect its stamp. Location is read live on your device to power this proximity check and the map views; RoamFolio does not track your location in the background, does not build a location history beyond the stamps you actually collect, and does not sell or share raw location data with anyone. If you're signed in, RoamFolio also sends your most recent location (and the location of the last stamp you collected) to the RoamPost service described below, so postcard delivery time can scale with the distance between you and a friend. Only the latest position is kept, it is never shown to anyone, and the service only ever reveals a rounded distance (to the nearest 250 km) to a friend you've connected with.
Photos
RoamFolio can read photo metadata in a few different ways, depending on the feature:
- Adding a past trip ("Retro-Add"): when you pick a photo from your library (via Apple's system photo picker, which does not grant RoamFolio ongoing library access) or share one in from Google Photos, Files, or another app, RoamFolio reads that single photo's embedded GPS coordinate and capture date to match it against nearby stamping stations. The photo is never stored or uploaded. If it has no embedded location, then on devices that support Apple Intelligence RoamFolio uses Apple's Vision framework on your device to read any text in the photo and label its scene, and passes that text to Apple's on-device language model to suggest which city it was taken in. This runs entirely on your device — neither the photo nor those clues are transmitted to us or any third party — and a suggested city is only ever offered for you to confirm, never added automatically. Otherwise only the location/date metadata is used, momentarily, to find a match.
- Sending a postcard, and viewing "Photos From This Trip": to help you pick a photo taken near a stamp — either while composing a postcard, or when browsing the photos your library has near a stamp you've already collected — RoamFolio requests broader photo library access for these features (iOS only offers a combined read/write permission level here; RoamFolio only ever reads your photos and never modifies or deletes them). It scans your library's location metadata to surface nearby matches; a photo you actively choose for a postcard is cropped on-device (Apple's Vision framework picks the most visually interesting area to keep, entirely on-device) and becomes part of a postcard you send — see "Sign in with Apple, Friends, and Postcards" below for how that's stored and shared.
Camera
The camera is used only to scan a friend's RoamPost QR code so you can connect with them. RoamFolio does not otherwise access the camera and does not store camera frames or images from this scan.
Stamps, badges, and friend activity you generate
The stations you've stamped and the dates you collected them, and the postcards you send and receive, are stored on your device and backed up to your own private iCloud account (via Apple's CloudKit) so they sync across your own devices. This data is private to your iCloud account — RoamFolio has no server that stores or has access to it. Your unlocked badge list and friend connections are also stored with your RoamPost profile, described below.
Name, avatar, and status
Your display name defaults to the name Apple shares with RoamFolio the first time you sign in (only ever provided on that first authorization, and only if you choose to share it); if you don't share a name, or want to change it later, you can set or edit it anytime from Account. It's used for your in-app greeting and shown to any friends you connect with. Your profile picture is a generated avatar rendered from your display name by a small image-rendering service Nossa operates and hosts itself, unless you choose to set your own photo from Account. A photo you choose is cropped and downsized on your device to a small square and uploaded to storage Nossa operates; friends you're connected with see it, and it can be viewed by anyone who has its long, unguessable link (which is only shared with you and your friends). You can switch back to the generated avatar at any time, which deletes the uploaded photo — see "Third-Party and Nossa-Operated Services" below. You can also set a short status line under your dashboard greeting ("What are you up to?") at any time; unlike your locally-stored stamps, this status is stored with your RoamFolio profile on Nossa's service so any friend you're connected with can see it on the Friends screen — see "Sharing With Other Users" below.
Sign in with Apple, Friends, and Postcards
RoamFolio has no separate account system of its own — Sign in with Apple, completed once during setup, is how you get an identity in the app at all, and there's currently no way to finish setup without it. What stays optional afterward is whether you actually use RoamPost, the social side built on top of that identity: connecting with friends and sending postcards. We store the opaque identifier Apple provides, your display name, a randomly generated friend code and invite code, your unlocked-badge list and status line, and your friend connections in a small database Nossa operates (on Cloudflare) — not in CloudKit. Adding a friend (by entering their code or scanning their QR code) sends that person a request through that service; the connection only becomes active once they accept it, and either side can remove the connection or block the other person afterward. When you send a postcard, its artwork (built from your chosen photo and stamp) and any short personal message you add are stored in a private, per-recipient CloudKit share that only you and that specific friend can access. Signing in also lets RoamFolio verify you for the optional coin wallet described next, and you can sign out again anytime from Account — your already-collected stamps keep working locally and via iCloud either way, since they don't depend on being signed in.
Coins and couriers (optional)
RoamFolio has an optional in-app currency ("coins") you can earn — for example, by collecting your first stamp, sending your first postcard, or referring friends who accept your requests — and spend on optional upgrades, like an Extra Postman (to send another postcard while your free Postman is out on a delivery), or extra passport pages and passports. This only applies if you've signed in with Apple; coins are not required to collect stamps or fill your passport. To stop a coin balance from being edited by tampering with the app's local storage, your balance and the history of how you earned or spent it are tracked in a small ledger Nossa operates and hosts itself (a Cloudflare Worker and database, not a third party), keyed only to the opaque, per-app identifier Apple's Sign in with Apple provides — the same identifier used for Friends/Postcards, not your name, email, or Apple ID itself. This ledger never sees your stamps, photos, postcards, or contacts, and RoamFolio does not currently offer any way to buy coins with real money.
Notifications (optional)
Once you've signed in with Apple, RoamFolio will ask for permission to send notifications so it can let you know when a postcard is delivered to you, when a friend request arrives, and when a postcard you sent reaches its recipient. Postcard alerts use a silent CloudKit push to wake the app so it can prepare the alert — the push itself carries no postcard content or message text, only enough to tell the app something needs checking. Friend-request and referral alerts are sent by Nossa's RoamPost service through Apple's push notification service (APNs); for that, your device's push token is stored with your profile (and removed if you delete your account), and the alert text includes the other person's display name. RoamFolio also sends an immediate, on-device notification whenever you earn bonus coins (e.g. your first stamp or first postcard) — this one doesn't involve a network push at all, it just reports something that already happened locally. Beyond the system-level permission, RoamFolio's own Notifications settings screen lets you turn postcard alerts and friend-request alerts on or off independently (the coins-earned notification doesn't have its own toggle yet). You can decline or later disable notifications entirely anytime in iOS Settings → Notifications → RoamFolio without affecting any other feature.
Usage analytics
We use TelemetryDeck, a privacy-focused analytics service, to understand how people use RoamFolio — which screens are visited, how many stamps are collected and from which flow, aggregate friend-discovery activity (e.g. that a friend code was submitted, not who was found), postcard and trail-passport milestones, and non-identifying error events when something fails. TelemetryDeck does not use advertising identifiers, does not track you across other apps or websites, and does not require an App Tracking Transparency prompt because it doesn't perform cross-app tracking.
2. How We Use Information
- To show you stamping stations near your current location and let you collect them.
- To match a photo's embedded location/date against nearby stations for retro-adding stamps, or to suggest a city on-device when a photo has no location, and to surface nearby photos for postcards or your stamp's photo gallery.
- To back up and sync your collected stamps and postcards across your own devices via iCloud.
- To store your RoamPost profile and friend connections so you and your friends can find and see each other, via a service Nossa operates.
- To scale postcard delivery time by the distance between you and a friend, using your most recent location, which is never shown to anyone.
- To power RoamPost's optional social features — friend requests, badge and status sharing between friends, and postcard delivery — for the parts of the app you actually choose to use beyond the required sign-in.
- To notify you, if you allow it, when a postcard or friend request arrives, or a postcard you sent has been delivered.
- To render a generated avatar image from your display name, or store and show the profile photo you choose, via our own self-hosted services.
- To track and update your optional coin balance and purchases, via our own self-hosted coin-wallet service, for signed-in users who use that feature.
- To carry out a full account deletion when you request one — removing your profile, stamps, badges, connections, postcards, and coin balance from every place RoamFolio stored them.
- To understand aggregate app usage and fix errors, via TelemetryDeck.
We do not use your information to serve third-party ads, and we do not sell your personal information.
3. Data Storage and Syncing
RoamFolio does not operate a general-purpose backend server for your data. Your collected stamps and postcards are stored using Apple's CloudKit, inside your own iCloud account; your RoamPost profile and friends live in a small service Nossa operates (described below):
- Your private database: your collected stamps sync only to your own devices, tied to your Apple ID.
- A shared, per-recipient record: a postcard you send, including any message you add, is placed in a CloudKit share scoped to you and the one friend you sent it to — not a public or queryable database.
- Postcard delivery pointer: a small pointer used to notify a recipient that a postcard is waiting is stored in CloudKit's public database, scoped to the RoamFolio app — containing only what's needed to make delivery work, never postcard photo content.
Two things live on services Nossa runs itself (Cloudflare Workers, a database and file storage), separate from iCloud. Your RoamPost profile: Apple's opaque per-app identifier, your display name, friend and invite codes, unlocked-badge list, status line, the location described above, your device's push token, your friend connections and requests, invite redemptions, and a profile photo if you set one. The optional coin wallet described above: your coin balance and a log of how you earned or spent coins, keyed to Apple's opaque per-app identifier rather than your name or Apple ID.
If iCloud is unavailable or you're signed out, RoamFolio's core stamp-collecting features keep working fully offline using on-device storage; only cross-device sync and postcards require iCloud (Friends require an internet connection).
4. Third-Party and Nossa-Operated Services
| Service | Purpose | What it sees |
|---|---|---|
| Apple CloudKit / iCloud | Stores collected stamps and postcards, plus a small postcard-delivery pointer | Whatever is described in "Data Storage and Syncing" above, governed by Apple's own privacy policy |
| Apple Sign in with Apple | Required identity, set up once during onboarding; also underlies the optional Friends/Postcards and coin-wallet features | An opaque user identifier; no profile data is requested |
| Apple Vision (on-device) | Frames the photo you pick for a postcard; reads text and scene labels from a photo with no location to suggest a city | Runs entirely on your device; nothing is transmitted |
| Apple Intelligence on-device language model | Suggests which city a photo with no location was taken in, from the text and scene labels Vision finds | Runs entirely on your device; nothing is transmitted to us or any third party |
| Nossa Avatar Service (self-hosted, not a third party) | Renders your generated profile avatar | Your display name (used as a rendering seed) and the resulting image size; operated by us on our own infrastructure, not shared with any outside company |
| Nossa RoamPost Service (self-hosted, not a third party) | Stores your profile, friend connections and optional profile photo, scales postcard delivery time by distance, and sends friend-request alerts | Apple's opaque per-app identifier (verified through your wallet session), display name, friend and invite codes, badge list, status line, your most recent location (never shown to anyone), push token, friend connections, and a profile photo if you set one; never your photo library, postcards, or contacts |
| Apple Push Notification service (APNs) | Delivers friend-request and referral alerts to your device | Your device's push token and the alert text, governed by Apple's own privacy policy |
| Nossa Coin Wallet Service (self-hosted, not a third party) | Tracks your optional coin balance and Extra Postman/passport/passport-page purchases | Apple's opaque per-app identifier (verified via a signed Sign in with Apple token), your coin balance, and a log of earn/spend events; never your name, stamps, photos, postcards, or contacts |
| Nossa Content Catalog (self-hosted, not a third party) | Delivers new stamp artwork and station, peak and trail-route listings without an app update | A read-only request for public content, so like any web request it sees your device's IP address; it receives no account, location, photo or stamp data |
| TelemetryDeck | Privacy-conscious usage analytics | Anonymous, aggregate usage signals (see "Usage analytics" above) |
5. Sharing With Other Users
RoamFolio has no public profiles, social feed, or searchable directory of users. Information is only shared with another person when you take a deliberate action to connect with them, or once they're already your accepted friend:
- Sharing your friend code or QR code shares that code (not your location or stamp history) with whoever you show it to.
- Sending or accepting a friend request shares your display name, avatar (including your profile photo, if you set one), status line, and unlocked badge progress with that friend, for as long as you're connected. Postcard delivery uses your approximate distance to a friend (rounded to 250 km) to set the delivery time; your location itself is never shown.
- Sending a postcard shares that specific postcard's artwork, any message you wrote, the stamped station's name, the date, and your display name with the one friend you sent it to.
6. Your Choices and Controls
- Permissions: Location, Photos, Camera, and Notifications access can each be reviewed or revoked anytime in iOS Settings → Privacy & Security, or Settings → RoamFolio. Declining a permission simply disables the feature that needs it (e.g., without location access, nearby stations won't be found; without notifications, you just won't get an alert for postcards and friend requests).
- Sign-in: Sign in with Apple is a required, one-time step during setup — there's currently no way to use RoamFolio, including basic stamp collecting, without completing it once. What's optional is everything built on top of it: you're never required to add a friend, send a postcard, or use the coin wallet, and you can sign out again anytime from Account (your already-collected stamps keep syncing via iCloud regardless of sign-in status). You can also decline any friend request, and remove or block a friend at any time from the Friends screen.
- Deleting your account: from Account → Delete Account, you can permanently delete your RoamPost profile, friend code, friend connections and requests, collected stamps, badges, sent and received postcards, and your coin balance — from CloudKit, our RoamPost service (including any uploaded profile photo), our coin-wallet database, and your device, in one flow. This is separate from, and more thorough than, simply deleting the app.
- Deleting the app: uninstalling RoamFolio removes all locally stored data. Because your stamps and postcards live in your own iCloud account, you can also remove that data separately via iOS Settings → [your name] → iCloud → Manage Account Storage; using the in-app account deletion above is the only way to also remove your RoamPost profile, friend data, and coin-wallet record.
7. Children's Privacy
RoamFolio is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us using the details below so we can address it.
8. Data Retention
Stamps and postcards persist for as long as your iCloud account retains them, or until you delete the app / remove that data from iCloud yourself. Your RoamPost profile, friend connections, and any profile photo, and your optional coin balance and its transaction log, persist until you delete your account, at which point they're removed from our services. Analytics signals sent to TelemetryDeck are anonymous and are not linked back to an individual identity we control.
9. Security
Your stamps and postcards live in your own iCloud account, so they inherit Apple's iCloud security and encryption protections; your RoamPost profile and friend data are held by Nossa-operated services on Cloudflare and are only accessible with a valid signed-in session. Postcards are stored in per-recipient CloudKit shares rather than a publicly queryable database, so only the intended recipient can access them. The coin-wallet service verifies your Sign in with Apple token cryptographically against Apple's own published keys before issuing it a session, and that session token is the only credential used for wallet and RoamPost requests afterward.
10. Changes to This Policy
If RoamFolio's data practices change materially — for example, if a future feature adds a new kind of data collection — we'll update this page and revise the effective date above.
11. Contact Us
Questions about this policy or how RoamFolio handles your data? Reach out at support@nossaapp.com.